Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

87 results about "Trusted system" patented technology

In the security engineering subspecialty of computer science, a trusted system is a system that is relied upon to a specified extent to enforce a specified security policy. This is equivalent to saying that a trusted system is one whose failure would break a security policy (if a policy exists that the trusted system is trusted to enforce).

Data circulation trusted system and device based on block chain and privacy calculation

The invention discloses a data circulation trusted system and device based on a block chain and privacy calculation, and relates to the technical field of trusted data. Comprising a data supply end, a data demand end and a credible supervision end, the data supply end comprises a digital identity identification module which is used for generating a dynamic digital identity according to an enterprise unified social credit code and an ISO industry classification code and submitting the dynamic digital identity to a first block chain of the credible supervision end for authentication; the mixed desensitization module is used for carrying out first 3-bit plaintext reservation and hash replacement on the sensitive field by adopting an AES-256 algorithm, binding a UTC timestamp to generate a desensitization record and uploading the desensitization record to a first block chain; and the zero-knowledge proof generation module is used for converting the privacy calculation result into a zero-knowledge proof voucher and pushing verification parameters to a sandbox environment of the data demand end. According to the invention, the security and privacy of data in a circulation link and the credibility of transactions are guaranteed, and the problems of privacy leakage, uncredible transactions, difficult supervision and the like possibly existing in data circulation are solved.
Owner:GUIZHOU DIGITAL INNOVATION HLDG (GRP) CO LTD

Systems and methods for utilizing cryptographic co-dependency across multiple roots of trust

Systems, devices, and methods are provided for cryptographic co-dependent across multiple roots of trust. A device may comprise two or more co-dependent roots of trust, such as a trusted execution environment (TEE) of a main application processor and a cryptographic subsystem comprising a cryptographic processor. A server may validate digital signatures generated by each co-dependent root of trust that is known for the device and then provide the device with cryptographic material that can be used to establish a shared secret. The shared secret may be used by the device to request the performance of a sensitive operation.
Owner:AMAZON TECH INC

Block chain database data management system for traceability application

PendingCN121958236AImplement forced bindingOptimize physical distributionDatabase distribution/replicationDigital data protectionPathPingTamper resistance
The invention discloses a traceability application-oriented block chain database data management system, particularly relates to the technical field of block chain database data management, and is used for solving the problems of easy data tampering and low verification efficiency caused by traceability data logic association and physical storage splitting. The method comprises the following steps: firstly, matching a parent physical sector offset through an association analysis module, determining a storage partition, and assembling a write-in instruction; then, a topology binding module executes a disk write operation, synchronously reads parent node hash and performs combinatorial operation in combination with a physical address to generate a topology binding check value bound with the physical position; the aggregation anchoring module uses a Merkel tree aggregation check value to generate a root fingerprint and perform uplink, and establishes an anchoring voucher; and finally, a path verification module positions a physical position according to the certificate, executes reverse recursive addressing and step-by-step Hash recalculation, and assembles a pedigree verification packet, so that a closed-loop trust system from physical storage to chain certificate storage is constructed, and the tamper-proof capability and verification efficiency of the traceability data are improved.
Owner:NANCHANG FEYNMAN SMART TECH CO LTD

Resource classification layer for constant request verification in zero trust systems

A method is disclosed for managing access in a telecommunications network by utilizing a resource classification layer. The method involves receiving a request at a resource classification layer from a sender to obtain an access token for a receiver service. The sender is associated with a user role that has specific permissions and access rights corresponding to a data sensitivity threshold. The request includes a data payload. A classification value for the data payload is assigned using one or more resource classification models, which are trained on a log of past data payloads. A data sensitivity score is generated by comparing the classification value to a scale of classification values. The method then indicates whether the access token can be granted to the sender by comparing the data sensitivity score against the data sensitivity threshold to verify authorization.
Owner:T MOBILE US INC

Zero trust authentication and authorization system

In some implementations, a zero trust system may deploy one or more policies for controlling access to a service associated with a first machine entity. The zero trust system may issue a machine identity that uniquely identifies a workload associated with a second machine entity. The zero trust system may receive telemetry data related to interactions between the service associated with the first machine entity and the machine identity that uniquely identifies the workload associated with the second machine entity. The zero trust system may use a machine learning model to detect a security threat associated with the first machine entity and / or the second machine entity according to the telemetry data. The zero trust system may update the one or more policies to remediate the security threat. The zero trust system may provide the one or more updated policies to the first machine entity.
Owner:CAPITAL ONE SERVICES LLC

Trusted starting system and starting method of trusted starting system

The invention provides a trusted startup system and a startup method of the trusted startup system, and belongs to the technical field of communication, the system comprises an on-chip ROM (Read Only Memory) located in a CPU (Central Processing Unit), a one-time programmable memory located in the CPU, a password acceleration engine located in the CPU and an FPGA (Field Programmable Gate Array) chip connected with the CPU, the system comprises an FPGA (Field Programmable Gate Array) chip, a startup firmware chip, a system file chip and a system file backup chip which are connected with the FPGA chip, an on-chip boot program stored in an on-chip ROM (Read Only Memory), a trusted password module stored on a password acceleration engine, and Feiteng basic firmware, Feiteng universal firmware and a trusted system which are stored in startup firmware, and the self-developed Linux system is stored in the system file and the system file backup. According to the method, the system and the system starting process are completely credible, including security, credibility and tamper-proofing of all files in the system starting operation process, and security starting and tamper-proofing of the system are ensured in a mode of combining software design and hardware design.
Owner:成都菁蓉联创科技有限公司

Multi-node mutual credit authentication method and system of public key infrastructure system

PendingCN121333634AUser identity/authority verificationCredential service providerEngineering
The invention discloses a mutual credit granting authentication method and system among multiple nodes of a public key infrastructure system, and relates to the big data and data security technology, and the method comprises the steps: accessing a real name verification service provider and an identity credential service provider through a regional management node; the verification module is used for verifying the accessed enterprise identities and signing and issuing digital certificates to the enterprise identities passing the verification; a regional management node is used for registering service child nodes for qualified enterprise identities, registering connector root nodes for enterprise identities participating in services, generating node identity unique identifiers, and signing and issuing digital certificates; and the connector root nodes and the service child nodes access the area management node, the connector root nodes access the service child nodes, and the connector root nodes access each other to complete related services. According to the embodiment of the invention, an identity-authority-business three-in-one automatic trust system is constructed, the reliability of node identity authenticity verification in a distributed environment is improved, and the certificate and authority management cost of manual intervention is reduced.
Owner:ZHONGDIAN DATA IND CO LTD +1

Zero-trust access control strategy generation method and system based on extensible attributes

The invention discloses a zero-trust access control strategy generation method and system based on extensible attributes, and the method comprises the steps: constructing an empty dynamic attribute space which comprises subject attributes, object attributes, environment attributes and permission attributes, collecting network security elements of subjects, objects, environments and permissions in a current zero-trust system, and storing the network security elements in the current zero-trust system; extracting basic attributes of each network security element according to user requirements, and adding the basic attributes into a dynamic attribute space; mapping subject attributes, object attributes, environment attributes and authority attributes in the dynamic attribute space with subject information, object information, environment information and authority information collected by the current zero-trust system; and selecting subject attributes, environment attributes, object attributes and permission attributes from the dynamic attribute space according to actual requirements, and configuring an attribute constraint range for each attribute, thereby generating an access control strategy. The problem that the access control strategy is difficult to generate due to the change of the network environment or the change of the user demand is effectively solved.
Owner:JUNENG SPECIAL COMM EQUIP CO LTD TOEC GRP

An access method, device, platform, equipment and medium of an intranet and extranet terminal

This invention provides a method, apparatus, platform, device, and medium for accessing internal and external network terminals. The internal and external network access platform is deployed with a software-defined boundary architecture, which includes a zero-trust system. The method includes: receiving communication connection requests from internal and external network terminals through the zero-trust system; responding to the communication connection requests by granting access permissions to the internet ports of the internal and external network terminals based on a door-knocking packet; establishing a communication connection with the internal and external network terminals based on the access permissions and receiving office business access requests from the internal and external network terminals; responding to the office business access requests, acquiring office data, and returning the office data to the workspace domain of the internal and external network terminals. The zero-trust strategy is implemented through the software-defined boundary architecture, utilizing internet port hiding technology to reduce internet exposure; and a zero-trust sandbox is used to provide security assurance by isolating internal and external network terminals in personal and workspaces, achieving internal and external network isolation during office work and maintenance.
Owner:CHINA TELECOM CORP LTD

A method and system for testing a boot-trust function of an sis trusted system

The application belongs to the field of trusted system testing, and discloses a kind of SIS trusted system booting trusted function test method and system, the application is by automatically constructing test environment and centralized configuration test case on automation test host, so that test process does not need manual setting device parameter one by one, avoid the problem of omission and inconsistency caused by manual configuration, improve the efficiency and accuracy of test preparation stage.In the application, the steps of automatically executing restart, modifying the verification object, restoring the file, etc. are performed by remotely connecting the device under test, which makes the process that originally requires manual repeated operation mechanized and repeatable, thereby reducing the risk of misoperation caused by manual intervention.In terms of trust measurement data collection, the trusted chain and measurement information are automatically sent to the test host after each start of the device under test, and the test host can obtain the complete measurement chain in a timely and systematic manner, avoiding the omission problem that may occur when manually comparing logs and PCR values.
Owner:HUANENG POWER INT CO LTD RIZHAO POWER PLANT +2

Data security docking method and system, electronic equipment and storage medium

The invention relates to the technical field of computers, and discloses a data security docking method and system, electronic equipment and a storage medium, and the method comprises the following steps: generating an asymmetric key pair based on a national cryptographic algorithm, securely storing a private key in a trusted execution environment, submitting registration information, obtaining a digital certificate, chaining certificate metadata, and establishing a trusted digital identity; obtaining an authentication request identifier and a random number, and generating a composite report; performing equipment registration state verification, hardware trust chain verification and public key certificate consistency verification on the composite report, generating a structured authentication result after the verification is passed, and uploading the structured authentication result for evidence storage; querying an on-chain authentication state, encrypting data by using a data key, encrypting the data key by using a public key obtained from an authentication result, and transmitting the encrypted data; and using the private key to decrypt the data key in the trusted execution environment, and using the data key to decrypt and process the encrypted data. According to the method, the operation process can be simplified, the data leakage risk is eliminated, and a globally audible trust system is established.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Real estate registration method and system based on block chain

The invention relates to the technical field of real estate registration, and discloses a real estate registration method and system based on a blockchain, and the system comprises a data collection module, a data encryption module, a blockchain storage module, and an information verification module.In the aspect of data security, public key encryption and private key decryption mechanisms effectively guarantee data privacy and security, and the data security is improved. Stealing and tampering are prevented; in terms of data integrity, block hash values are compared through an information verification module, whether transmission data are changed or not is accurately judged, and completeness and reliability of the transmission data are ensured; the identity verification checks the signature validity by means of a digital certificate and a root certificate, constructs a security trust system, and prevents illegal operation; the multi-node alliance reduces the single-point fault risk, and the data change history can be checked to facilitate audit supervision; on the whole, the transparency, the fairness and the credibility of real estate registration are improved, the registration process is optimized, the processing capacity and the response speed are improved, the pain point of a traditional mode is solved, and efficient and healthy development of real estate registration business is promoted.
Owner:临沂润恒信息科技有限公司

A method for constructing a decentralized public key infrastructure based on a blockchain and a trust network

The application discloses a kind of decentralized public key infrastructure based on blockchain and trust network construction method, belong to information security PKI public key infrastructure field, including the following steps: step one, build decentralized CA agency;Step two, user submits certificate application / update / revocation request.Certificate request of user is submitted to decentralized CA agency, and the service of decentralized CA agency will call blockchain to generate / update / revocation digital certificate;Step three, certificate request of user is verified using blockchain technology.Certificate request is verified using smart contract technology.The decentralized public key infrastructure based on blockchain and trust network construction method aims to solve the single point of failure, certificate opacity, certificate revocation time-consuming and other problems existing in traditional PKI system, focuses on realizing that CA agency will not cause PKI trust system to collapse due to CA agency failure in the process of certificate life cycle management, while realizing certificate transparency and improving certificate revocation efficiency.
Owner:KOAL SOFTWARE CO LTD

A trust system for managing overseas funds and domestic foreign currency doposits

The present invention relates to a trust system for managing overseas funds and domestic foreign currency deposits. To this end, a trust system for managing overseas funds and domestic foreign currency deposits according to one embodiment of the present invention comprises: a fund manager server that provides a foreign currency operation fund instruction to a bank server; and the bank server including an asset custody system that receives the foreign currency operation fund instruction and an integrated financial system that generates transaction details by currency. The bank server, based on the foreign currency operation fund instruction received from the fund manager server, increases or decreases the balance of the fund, links the asset custody system and the integrated financial system to generate a message regarding the increase or decrease in the fund balance and proceeds with multiple settlements, performs linked processing for incoming remittances that increase the fund balance and outgoing remittances that decrease the fund balance in the integrated financial system, and at the daily closing, can verify whether the funds match between the deposit and withdrawal balance details of each fund and the foreign currency trust account.
Owner:WOORI FINANCIAL GROUP

Intranet security operation and maintenance method and device based on bastion host, medium and program product

The embodiment of the invention provides an intranet security operation and maintenance method and device based on a bastion host, a medium and a program product, and relates to the technical field of operation and maintenance management. The method comprises the following steps: in response to a connection request actively initiated by a zero-trust proxy client, establishing an end-to-end encrypted application layer tunnel between a zero-trust proxy server and the zero-trust proxy client under the condition that bidirectional authentication is passed; acquiring context information corresponding to the operation and maintenance terminal, and determining a dynamic authorization strategy based on the context information; and performing operation and maintenance management and control on the operation and maintenance operation of the operation and maintenance terminal based on the dynamic authorization strategy, and transmitting operation and maintenance traffic generated between the operation and maintenance terminal and the intranet resource side through the application layer tunnel. According to the embodiment of the invention, the zero-trust system model taking the internal resource side as the active connection end is constructed, and the dynamic authorization strategy is generated by acquiring the related context information in real time, so that the security of internal network operation and maintenance is greatly improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Message protection method and system for Internet of Vehicles

The invention belongs to the technical field of Internet of Vehicles security, and provides a message protection method and system for Internet of Vehicles, and the method comprises three parts: dynamic encryption algorithm adaptation, distributed trust authentication and abnormal message detection, and achieves the all-around security protection of Internet of Vehicles messages. And the dynamic encryption algorithm adaptation part can adaptively select the most suitable encryption algorithm to ensure the security and confidentiality of the message. The distributed trust authentication part carries out identity verification and trust evaluation on each node in the Internet of Vehicles by constructing a distributed trust system. In the message abnormity detection part, abnormal messages are found and processed in time by utilizing a machine learning algorithm; the message subjected to encryption protection is transmitted to the target node, the whole process of Internet of Vehicles message protection is completed, the method is suitable for a multi-node scene formed by a vehicle-mounted terminal, roadside equipment and a cloud platform, and the technical problems that in Internet of Vehicles message transmission, real-time performance and safety are unbalanced, cross-domain authentication efficiency is low, and abnormal messages are lagged can be solved.
Owner:WUXI UNIV

Virtual resource allocation method and device and electronic equipment

The embodiment of the invention discloses a virtual resource allocation method and device and electronic equipment. The scheme comprises the steps of obtaining attribute information of a target user and a public key corresponding to the user, constructing a distributed identity for the target user according to the attribute information and the public key, determining a target allocation type according to an allocation request in response to the received allocation request for target virtual resources sent by the target user, and allocating the target virtual resources according to the allocation request and the distributed identity. And determining a target allocation type, obtaining a corresponding target allocation strategy according to the target allocation type, and allocating the target virtual resources between the target user and the receiver according to the target allocation strategy. According to the embodiment of the invention, on the basis of efficiently and flexibly allocating the target virtual resources according to a distributed account book technology, autonomous control of the target user on the identity data is enhanced, the privacy protection level is improved, cross-system interoperability is realized, and basic support is provided for a digital trust system.
Owner:CHINA MOBILE INTERNET CO LTD +1

Virtual social relation construction method and system based on meta universe

The invention discloses a virtual social relationship construction method and system based on meta universe. The method comprises the following steps: creating a user personalized virtual image based on user identity information; establishing a social space and establishing emotion connection through the virtual image of the user; personalized recommendation is customized according to the behavior data information of the user; according to the method, the social relation between the virtual users is maintained on the basis of historical record information, the virtual social relation between the users with different virtual images is maintained by designing corresponding social mechanisms in different virtual social spaces, and privacy information and safety of the users can be effectively ensured on the basis of the social mechanisms; and corresponding functions are provided to protect the rights and interests of the users, and meanwhile, a reputation and trust system is utilized to maintain specifications and orders in the virtual social space, so that the rights and interests of different virtual users are further guaranteed, and a healthy and harmonious community atmosphere of the social space is maintained.
Owner:苏州和数智能软件有限公司

Digital document with enhanced security and tracking

PendingUS20260099612A1Digital data protectionEmbedded securityData set
Systems and methods for generating digital documents with embedded security features are provided. Methods may include receiving a first dataset comprising content data that was manually inputted by a system user, receiving a second dataset comprising an identifier associated with the system user, receiving a third dataset comprising a location associated with the system user, and cryptographically embedding, via a machine-learning (ML) module, the second and the third datasets into the first dataset to create a fourth dataset. In the fourth dataset, the first dataset may be visible to a human viewer while the second and the third datasets are invisible, and the second and third datasets may be extractable by a trusted system in possession of a cryptographic key. Methods may include generating an output document displaying the fourth dataset.
Owner:BANK OF AMERICA CORP

Network access scheme based on zero-trust system

The invention provides a network access scheme based on a zero-trust system, which comprises the following steps of: creating a new three-layer tunnel network interface at an access client of an SDP, and configuring an ip as an internal ip; the control server connected with the SDP rear end obtains the corresponding relation between the self-defined domain name of the protected server at the rear end and the virtual ip; starting a dns service at a three-layer tunnel network interface, and importing a corresponding relation between a user-defined domain name and a virtual ip; modifying a local dns server address, and pointing to a local ip; after the configuration is completed, the user can access the back-end application service protected by the SDP through the user-defined domain name. According to the network access scheme based on the zero-trust system, the local DNS resolution server is introduced into the access client of the SDP, and the internal service protected by the SDP can be conveniently accessed by a final user through a self-defined domain name address.
Owner:QINGLAN DATA SECURITY TECH (BEIJING) CO LTD

Method and apparatus for generating authenticated user data

This document discloses a computer-implemented method for providing a verified certificate that will be modified during the generation of authenticated user data. It also discloses a computer-implemented method for enabling the representation of an unknown user from authenticated user data, and a method for representing the unknown user from the authenticated user data. The generation of the authenticated user data avoids the risk of personal information being leaked into the digital domain, except where it is necessary to represent or identify an unknown user with the assistance of a trusted system.
Owner:SW7 VENTURES (H K) LTD

Trusted cloud level standardization framework system and quantitative mapping method

ActiveCN121585482Bsolve the messSolve the repeatabilityInformation securityTrusted system
The application belongs to the technical field of information security, and provides a trusted cloud level standardization framework system and a quantitative mapping method, which is executed by one or more processors deployed on a server or an authentication platform, is based on a predefined trusted cloud level standardization framework system and a unified data security level measurement, and comprises the following steps: a receiving step of receiving qualitative security control items from an external standardization framework; and an automatic process of "parsing-mapping-evaluating-generating" for converting the external qualitative control items into digital levels based on the unified measurement, which not only improves the traditional compliance judgment from binary qualitative to fine quantitative, realizes accurate comparison of security capabilities, but also provides a core technical path for realizing automatic compliance evaluation, generating intuitive and trusted credit scores, and constructing an end-to-end verifiable supply chain trust system.
Owner:WUHAN TRUSTED CLOUD TECH CO LTD

A trusted system for decentralized data storage

Certain aspects of the present disclosure provide techniques for proving possession of data in a storage device participating in a distributed data storage network. An exemplary storage device includes a storage circuit system and a trusted circuit. The storage circuit system is configured to store a plurality of data blocks. The trusted circuit typically has a private signature key securely stored thereon. The trusted circuit is typically configured to calculate a hash of the data stored in the plurality of data blocks and generate an anonymous digital signature for the data stored in the plurality of data blocks based at least in part on the private signature key and the calculated hash. The trusted circuit can be inserted into a write path of the storage circuit system so that data written to the storage circuit system is processed by the trusted circuit.
Owner:WESTERN DIGITAL TECHNOLOGIES INC

Trusted system for providing customized content to internet service provider subscribers

A method includes receiving, by a processing system of a user endpoint device, a network cookie directly from an internet service provider who provides a subscriber who is associated with the user endpoint device with connectivity to the internet, storing, by the processing system, the network cookie in a local memory of the user endpoint device, generating, by the processing system, a request to send to the Internet service provider, wherein the request comprises a request for an internet protocol address associated with a uniform resource locator of an internet content provider, attaching, by the processing system, the network cookie to the request, and sending, by the processing system, the request including the network cookie to the Internet service provider.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Cryptographic trust system for electronic communications integrity using tuple spaces and messaging user agents

An electronic communication system for certification of an electronic communication includes: (1) a cryptographic trust server (CTS); (2) a common memory to store electronic communications; (3) a tuple server configured to generate tuple spaces; (4) a first user device; and (5) a first messaging user agent (MUA) associated with the first user device. The first MUA is configured to generate an MUA cryptographic hash for a first electronic communication, and the MUA places the first electronic communication with the cryptographic hash in the common memory, optionally with an iterative communication thread of prior electronic communications. The first MUA places an alert and the location of the first electronic communication in a tuple space provided by the tuple server. The alert notifies the CTS to access the common memory to review and verify or not verify the MUA cryptographic hash and optionally verify or not verify a CTS hash of the iterative communication thread.
Owner:MITEL CORP

Construction method of trusted root architecture and application method and device of trusted system

The invention relates to a construction method of a trusted root architecture and an application method and device of a trusted system. The method comprises the following steps: performing entity division on a trusted root on a hardware entity in a server to obtain a plurality of trusted root instances, and performing interface docking on a target trusted root instance in the plurality of trusted root instances and a main system in the server, and performing interface docking on other trusted root instances in the plurality of trusted root instances and a plurality of virtual machines in the server to construct a trusted system of the plurality of trusted root instances. According to the construction method, the trusted roots corresponding to all the trusted computing systems run in the hardware entity and are protected by the hardware entity, the security of each trusted system can be improved, the trusted root instance in each trusted system can directly call the data processing module of the hardware to process data, and the data processing efficiency is improved. The method is not limited by a software data processing algorithm, and can greatly improve the data processing rate, thereby improving the data processing performance of each trusted system.
Owner:SUGON INFORMATION IND +1

Federated digital rights management scheme including trusted systems

Federated systems for issuing playback certifications granting access to technically protected content are described. One embodiment of the system includes a registration server connected to a network, a content server connected to the network and to a trusted system, a first device including a non-volatile memory that is connected to the network and a second device including a non-volatile memory that is connected to the network. In addition, the registration server is configured to provide the first device with a first set of activation information in a first format, the first device is configured to store the first set of activation information in non-volatile memory, the registration server is configured to provide the second device with a second set of activation information in a second format, and the second device is configured to store the second set of activation information in non-volatile memory.
Owner:DIVX LLC

A federated distributed trusted reference value management method and system

Embodiments of the present application relate to a kind of joint distributed trusted reference value management method and system, comprising: obtaining trusted reference value file, wherein, trusted reference value file is generated when target firmware updates, trusted reference value file carries at least file identification and firmware identification;Obtain the storage index information obtained when reference value file is stored in distributed manner;File identification and storage index information are associated and stored to joint distributed trusted system, and the key storage information corresponding to firmware reference value file is generated, wherein, key storage information includes transaction information;Non-balanced hash block tree is constructed based on key storage information, and non-balanced hash block tree is used to verify any one transaction information of joint distributed trusted system, whereby, the correctness of the index value of the reference value file obtained can be verified quickly, to further guarantee the correctness of reference value, reduce the security risk caused by single manufacturer centralized management private key leakage.
Owner:GLOBAL ENERGY INTERCONNECTION RES INST CO LTD +3

Comprehensive management system based on smart funeral

The invention belongs to the technical field of information management systems, discloses a comprehensive management system and method based on a smart funeral, and aims to solve the problems of security risk of static associative storage of sensitive data, default dormancy of the system, mutual isolation of a citizen identity database and a funeral affair database, encryption of identity information, deidentity of affair information and insecurity of the system. A unique indirect connection is established between the trusted execution environment and the trusted execution environment through an asymmetrically encrypted associated handle, only when a legal query request authenticated by the trusted system is received, the system is temporarily activated, the handle is decrypted in the trusted execution environment, data fusion is instantaneously completed in the memory to generate an authorized view, and after a session is finished, the authorized view is generated. And the system immediately returns to an isolated dormant state, and the temporary data in the memory is thoroughly destroyed. Through the design of static isolation and dynamic fusion, the security and compliance of highly sensitive data are fundamentally guaranteed.
Owner:HANGZHOU ANCHUANG TECH CO LTD

Remote access via system-level trusted authorities

Methods and systems for establishing a system specific trust system are provided. The methods and systems establish a secure channel between a first device and a second device using a system specific trusted authority. The methods and systems determine, by the first device, using a first certificate associated with the second device, a first set of access rights of the second device and determine, by the second device, using a credential associated with the first device, a second set of access rights of the first device.
Owner:ASSA ABLOY AB